<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic yes thank you kanwaljeet I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641830#M194717</link>
    <description>&lt;P&gt;yes thank you kanwaljeet I agree with you regarding having a NAT instead of replacing the Outside ip because I will have to then change many other things inclusive of routing and arp tables so it would be very good to have the object and nat all the required subnets to the PIX outside ip with static route on edge router.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the arp table I should only clear the arp table on all the devices or simply on core and edge device would be suffice....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2015 17:56:09 GMT</pubDate>
    <dc:creator>usman ali dar</dc:creator>
    <dc:date>2015-04-23T17:56:09Z</dc:date>
    <item>
      <title>Migration from PIX 6.0 to ASA 9.0</title>
      <link>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641827#M194714</link>
      <description>&lt;P&gt;we have an old pix that we are migrating to ASA 9.0 everything seems good regarding configuration's and migration of all services,&amp;nbsp;the issue I am facing is that I have some or many applications that is stick to the interface ip because it is dynamically&amp;nbsp;NATTED outside&amp;nbsp;in old days and now when all the migrations can be done but not that IP it might break many application services or issue which is not good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions or ideas how can I work around with this..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any thoughts if I change the outside ip of new firewall ASA with Old firewall Outside IP what will happen to ASA or I should not do that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot create another or sub interface because the new firewall and the old firewall is in the same subnet.....&lt;/P&gt;&lt;P&gt;old firewall 192.168.100.1/24&lt;/P&gt;&lt;P&gt;new firewall 192.168.100.2/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I cannot also use secondary ip address option on the ASA......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only option or solution that I can think of is use the outside interface IP of the old PIX and use it to NAT dynamically all of the objects and object-groups that is actually natted in PIX and get the routing configured for that outside ip towards new ASA .....however this is just a thought .....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any suggestions please...&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641827#M194714</guid>
      <dc:creator>usman ali dar</dc:creator>
      <dc:date>2019-03-12T05:49:36Z</dc:date>
    </item>
    <item>
      <title>Hi Usman,You can use the PIX</title>
      <link>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641828#M194715</link>
      <description>&lt;P&gt;Hi Usman,&lt;/P&gt;&lt;P&gt;You can use the PIX outside IP and create NAT rules on ASA. Just ensure that routing is fine and ASA will nat the traffic. You don't need to assign the IP on an interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, depending upon your requirement you can even assign it on outside interface but then existing rules on ASA&amp;nbsp;would be impacted too. If you don't want that, just nat the network with IP that is on PIX(and now asa will answer arp for it), take care of the routing and shut down pix interface and everything should be fine.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 17:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641828#M194715</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-04-23T17:24:40Z</dc:date>
    </item>
    <item>
      <title>Hi Usman,You can use the PIX</title>
      <link>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641829#M194716</link>
      <description>&lt;P&gt;Hi Usman,&lt;/P&gt;&lt;P&gt;You can use the PIX ip on your new ASA(create object) and use it for NAT. No need to define it on the interface. ASA will nat it and answer arp for this IP. Depending upon your requirement you can even use the PIX IP on outside interface but your existing rules will be impacted too.&amp;nbsp; Clear xlate if you chose the latter and it should work fine. If you chose the former ensure that routing is properly taken care of and it should work just fine.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 17:26:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641829#M194716</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2015-04-23T17:26:56Z</dc:date>
    </item>
    <item>
      <title>yes thank you kanwaljeet I</title>
      <link>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641830#M194717</link>
      <description>&lt;P&gt;yes thank you kanwaljeet I agree with you regarding having a NAT instead of replacing the Outside ip because I will have to then change many other things inclusive of routing and arp tables so it would be very good to have the object and nat all the required subnets to the PIX outside ip with static route on edge router.....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for the arp table I should only clear the arp table on all the devices or simply on core and edge device would be suffice....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 17:56:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/migration-from-pix-6-0-to-asa-9-0/m-p/2641830#M194717</guid>
      <dc:creator>usman ali dar</dc:creator>
      <dc:date>2015-04-23T17:56:09Z</dc:date>
    </item>
  </channel>
</rss>

